ETSI TS 132 371-2017由欧洲电信标准协会 IX-ETSI 发布于 2017-04-01。
ETSI TS 132 371-2017 在中国标准分类中归属于: M11 通信网技术体制。
ETSI TS 132 371-2017 数字蜂窝通信系统(第2+阶段)(GSM全球通信系统);通用移动通信系统(UMTS);长期演进技术(LTE);通信管理;安全管理概念和要求(V14.0.0;3GPP TS 32.371版本14.0.0 发行版本14)的最新版本是哪一版?
最新版本是 ETSI TS 132 371-2024 。
The present document defines, in addition to the requirements defined in 3GPP TS 32.101 [1] and 3GPP TS 32.102 [2], the requirements for Security Management IRP. The purpose of the present document is to specify the necessary security features, services and functions to protect the network management data, including Requests, Responses, Notifications and Files, exchanged across the Itf-N. Telecommunication network security can be breached by weaknesses in operational procedures, physical installations, communication links, computational processes and data storage. Of concern here in the present document is the security problems resulting from the weaknesses inherent in the communication technologies (i.e., the 3GPP-defined Interface IRPs and their supporting protocol stacks) deployed across the Itf-N. Appropriate level of security for a telecommunication network is essential. Secured access to the network management applications, and network management data, is essential. The 3GPP-defined Interface IRPs (and their supporting protocol stacks), deployed across the Itf-N, are used for such access, and therefore, their security is considered essential. Many network management security standards exist. However, there is no recommendation on how to apply them in the Itf-N context. Their deployment across the Itf-N is left to operators. The present document and the corresponding solutions identify and recommend security standards in the Itf-N context. The business case for secured Itf-N is complex as it does not relate to the functions of the Interface IRPs (the functions are constant) but rather, it relates to variants such as the cost of recovering from security breaks, the probability of security incidents and the cost of implementing Security Management, all of which differs depending on specific deployment scenarios. The present document describes the security functions for a 3G network in terms of Security Domains (subclause 4.1). Clause 5 defines the Itf-N Security Management scope in terms of its context (subclause 5.1) and the possible threats that can occur there are defined in clause 6. Clause 7 specifies the Itf-N security Requirements.
| 术语 | 描述 |
|---|---|
| 访问控制 access control | 防止未经授权使用资源,包括防止以未经授权的方式使用资源。 |
| 责任 accountability | 确保实体的行为可以唯一地追溯到该实体的属性。 |
| 认证 authentication | 包括数据源认证和对等实体认证,见ITU-T建议X.800。 |
| 授权 authorization | 授予权利,包括基于访问权利的访问授予。 |
| 可用性 availability | 属性,指在需要时可以被授权实体访问和使用。 |
| 机密性 confidentiality | 属性,指信息不向未授权的个人、实体或进程提供或披露。 |
| 凭证 credentials | 用于建立实体声称身份的数据。 |
| 密码学 cryptography | 体现用于转换数据的原理、手段和方法的学科,以隐藏其信息内容,防止未经美利体育登录入口官网的修改和/或防止未经授权使用。 |
| 数据完整性 data integrity | 属性,指数据未经未授权的方式改变或破坏。 |
| 数据源认证 data origin authentication | 证实接收到的数据源与声称的一致。 |
| 拒绝服务 denial of service | 防止对资源的授权访问或延迟时间关键操作。 |
| 数字签名 digital signature | 附加到数据单元或数据单元的加密变换,允许接收方证明数据源的完整性和真实性,并防止伪造。 |
| 窃听 eavesdropping | 通过监控通信破坏机密性。 |
| 伪造 forgery | 实体伪造信息并声称该信息是从另一实体接收的或发送到另一实体的。 |
| 集成参考点 Integration Reference Point (IRP) | 参见3GPP TS 32.150。 |
| IRP代理 IRPAgent | 参见3GPP TS 32.150。 |
| IRP管理器 IRPManager | 参见3GPP TS 32.150。 |
| 信息丢失或损坏 loss or corruption of information | 传输的数据完整性因未授权的删除、插入、修改、重新排序、重放或延迟而受损。 |
| 操作系统 Operations System (OS) | 指独立于其在管理层级中位置的管理系统通用术语。 |
| 伪装 masquerade | 实体假装是另一实体。 |
| 密码 password | 保密的认证信息,通常由一串字符组成。 |
| 对等实体认证 Peer Entity Authentication | 证实关联中的对等实体是被声称的那个。 |
| 否认 repudiation | 参与通信的一方否认其参与了全部或部分通信。 |
| 安全审计 security audit | 对系统记录和活动进行的独立审查和检查,以测试系统控制的充分性,确保符合既定政策和操作程序,美利体育登录入口官网安全违规行为,并建议任何必要的控制、政策和程序变更。 |
| 威胁 threat | 潜在的违反安全的行为。 |
| 未授权访问 unauthorized access | 实体试图违反现行安全策略访问数据。 |

点击查看大图
| 网络元素 未提及 | 网络中的物理或逻辑组件,如基站、交换机等,作为管理对象。 |
Copyright ?2007-2026 ANTPEDIA, All Rights Reserved
京ICP备07018254号 京公网安备1101085018 电信与信息服务业务经营许可证:京ICP证110310号
页面更新时间: 2026-07-24 15:53